Six failure points

Enterprise information security, built around what actually goes wrong

Security is not a product but a set of specific things that go wrong, each answered by a control that sits somewhere particular. ILS Networks designs and builds that set — firewalls, segmentation, access control and endpoint protection.

Illustration: an enterprise security estate — perimeter firewall, internal segmentation and endpoint protection

Overview

We take responsibility for the security layer end to end

ILS Networks designs, builds and operates the enterprise security estate: the firewall at the perimeter, internal segmentation, remote access and access control, and endpoint protection across workstations and servers. We also take over existing estates — mapping and documenting the policy already running before touching it, and only then taking on operations.

The work follows a fixed method: mapping before any change, maintenance windows the organization defines, a way back at every stage, acceptance testing and full documentation of what is handed over. That is how projects finish on the date that was set rather than drifting.

We are official partners of Fortinet, Sophos and Palo Alto Networks, and implement endpoint protection on ESET and SentinelOne. These are the platforms we work with most, not a closed list. If something else runs in your estate, we will design, build and maintain that too.

We work with organizations over years rather than over a single project — Ariston Group for around six years running the entire estate, Combe for more than fifteen, CooperVision and Galmarine for about five each.

Why invest in security

What it is worth on the day something goes wrong

Security is measured on the bad day, not on an ordinary one. These are the practical differences between an estate that is protected and one that is relying on nothing happening.

Downtime costs more than prevention

A ransomware event takes an organization down for days, not hours. The cost of the outage, the restore and the recovery is almost always higher than the controls that would have prevented it.

Whoever gets in does not reach everything

Internal segmentation confines the damage to the area that was breached. Without it, one infected workstation gives access to everything on the same network.

Remote access you can explain

Who is entitled, to what, and since when — documented and managed. Access opened "temporarily" two years ago is one of the most common gaps we find.

The endpoint protected, not only the perimeter

Most incidents start on an endpoint rather than at the firewall. Endpoint protection under one policy stops what has already passed the gate.

A policy that can be maintained

A documented configuration you can read and explain, instead of a rule list that accumulated. That is the difference between a change taking minutes and an investigation taking a day.

Knowing what happened, and when

Monitoring and logging of what was blocked and who connected. Without it, there is no way after an incident to know what was touched and what was not.

The map

What goes wrong, and what stops it

Six failure points we actually see in enterprise environments, and the control that answers each.

What goes wrong

A branch wired straight into the central network with no control of its own

The control

A firewall at the branch and uniform policy across sites

Firewalls & network security
Where it sits

At every site

What goes wrong

Information-security requirements set by a customer, supplier or government body

The control

Hardening, written policy and documentation you can present

Where it sits

Across the estate

The platforms

The platforms we specialise in

Each platform has its own page with the scope and the process. The choice follows the environment, the sites and the budget.

Fortinet Official partner Firewalls, VPN and segmentation Firewalls & network security
Sophos Official partner Firewalls and controlled branch connectivity Firewalls & network security
Palo Alto Networks Official partner Next-generation firewalls and traffic control Firewalls & network security
Sophos / ESET / SentinelOne Official partner EDR across endpoints and servers, with managed MDR on Sophos or ESET Full page

Proof

Security built in live enterprise environments

Ariston Group

Centralized security stack and branch connectivity

Deployment of a Sophos-based security infrastructure with branch sites connected over Sophos RED — every location managed under a single, central security policy.

  • Sophos
  • Sophos RED

Combe

Firewalls and enterprise switching

Sophos firewalls deployed alongside Arista switches — the security layer and the network layer designed and built as one system.

  • Sophos
  • Arista

Prigat

Enterprise core switching

An Arista-based core switching fabric built as the site's central communications infrastructure.

  • Arista

Galmarine

Switching infrastructure upgrade

Deployment of Arista switches and an upgrade of the enterprise network infrastructure.

  • Arista

ILS Networks has been designing and operating enterprise networks and security infrastructure in Israel.

FAQ

Questions and answers

Which security vendors do you work with?

We are official partners of Fortinet, Sophos and Palo Alto Networks at the firewall layer, and of ESET and SentinelOne at the endpoint. Working with several is deliberate: different environments suit different platforms, and we do not want the recommendation driven by what we happen to sell.

What is network segmentation, and why is it the control most often skipped?

Segmentation divides the network into zones kept apart from each other, so reaching one does not automatically mean seeing the rest. It gets skipped because it is invisible — there is no box to buy and no dashboard proving it works. But it is the control that decides whether an incident stays local or becomes an organization-wide event.

We have a good firewall. Is that not enough?

A firewall handles the perimeter. It does not handle lateral movement inside the network, an endpoint infected by a file a user opened, or remote access that was opened and forgotten. Those are different controls sitting in different places — which is exactly what the map on this page shows.

Can you help us meet security requirements set by an external body?

Yes. In practice that is a combination of hardening the environment, written access policy and documentation you can present. At Combe we prepared the organization to meet information-security requirements set by government institutions. Requirements differ between bodies, so the work starts by mapping exactly what is being asked rather than assuming.

Do you handle the network itself — switching, Wi-Fi and branch connectivity?

Yes, but that is a different layer with its own page. The network layer — core, Campus, wireless and site connectivity — is covered on the networking page. Here we focus on the security controls that sit on top of that network.

Do you monitor the environment after it is built?

Yes. Ongoing monitoring, alert handling, version updates run as controlled changes, and coverage checking — which machines are not reporting. Support runs alongside the rest of the infrastructure, because a security incident does not wait for office hours.

How does Israel's Privacy Protection Amendment 13 affect IT infrastructure?

Amendment 13 broadened the duties around protecting databases and the personal accountability of management. We are not legal advisers and we do not issue compliance certificates — but most of the requirements rest on infrastructure controls we do build: access control and permissions, network segmentation, encryption, documentation, monitoring, and backup you can actually restore from. The legal guidance itself should come from a qualified adviser.

What does ILS do in security, and what does it not do?

We build and operate the infrastructure defence layers: firewalls, segmentation, VPN, access control, endpoint protection and EDR, and tested backup. What we do not do: we are not a 24/7 monitoring SOC, we do not run penetration tests, and we do not issue standards certifications. Where an organization needs those, we say so rather than take the work.

What actually stops ransomware?

Not one tool but a combination: a firewall inspecting traffic, segmentation that prevents lateral spread, minimized privileges, behaviour-based endpoint protection, and backup with a copy that cannot be deleted from the compromised machine. The layer most often skipped is segmentation, and it is the one that decides whether an incident stays local or spreads.

Start by mapping what is covered and what is not

A short technical call: what is installed today, which points on the map are already covered, and where the largest gap is. No commitment.

Your details are used to respond to your inquiry, as described in our privacy notice.

Talk to us